Security Trust Center

Review the controls for production agents

Current security, privacy, hosting, and review information for teams that evaluate Duale AI.
Review subprocessors

Controls available today

These controls apply to the managed Duale AI service.
  • Application encryption

    Duale AI encrypts Library source files, extracted content, search data, database backups, and reporting copies before storage. The exact method depends on the data category.

  • Tenant isolation

    Authenticated credentials identify the tenant and agent. The platform applies tenant-scoped authorization to tasks, Libraries, hosted tools, and cached data.

  • Operational evidence

    Task state, errors, retries, routing decisions, and audit events give teams evidence for incident review and production operations.

  • EU hosting

    Hetzner hosts managed application data in Germany. Cloudflare provides website delivery and network protection. Customers select their model providers and the regions those providers use.

Review material

Use the public documents first, then request deployment-specific material.
  • Deployment review

    Customers can request the data-processing agreement, security questionnaire, architecture summary, incident path, and other material that applies to their deployment.

Data and provider boundaries

  • Managed service

    Duale AI operates the application, its service keys, and its managed infrastructure. A customer-hosted deployment is also available for eligible customers that need to operate the platform in their own infrastructure.

  • Model providers

    Customers choose and contract with their model providers. Duale AI routes work only to providers enabled for the deployment.

  • Training use

    The privacy notice, customer agreement, and selected model-provider contracts define whether data can be used for training.

Contact paths

Security review questions

Review the controls for your deployment.

Read data protection